BugTraq
Internet Explorer URL parsing vulnerability Dec 09 2003 06:15PM
John W. Noerenberg II (jwn2 qualcomm com) (1 replies)
Re: Internet Explorer URL parsing vulnerability Dec 10 2003 12:13AM
Pedro Castro (noupy mail telepac pt) (3 replies)
Re: Internet Explorer URL parsing vulnerability Dec 10 2003 07:39PM
William Stockall (wstockal compusmart ab ca)
Re: Internet Explorer URL parsing vulnerability Dec 10 2003 07:37PM
Tiago Pierezan Camargo (tiago telenova net)
Re: Internet Explorer URL parsing vulnerability Dec 10 2003 07:26PM
Andreas Plesner Jacobsen (apj mutt dk) (1 replies)
Re: Internet Explorer URL parsing vulnerability Dec 11 2003 12:43AM
Charles Richmond (cmr iisc com) (1 replies)
Using the POC at http://www.zapthedingbat.com/security/ex01/vun1.htm

The following do NOT have the vulnerability.

MacOSX 10.2.28 Mozilla Firebird 0.6 NOT vulnerability
MacOSX 10.2.28 Mozilla Firebird 0.7.1 NOT vulnerability
MacOSX 10.2.28 IE 5.2.2 (5010.1) NOT vulnerability
MacOSX 10.2.28 IE 5.2.3 (5815.1) NOT vulnerability

With both Firebird and IE the following is the same result. The
line below is a cut/paste.

http://www.microsoft.com%01 (at) zapthedingbat (dot) com [email concealed]/security/ex01/vun2.htm

Someone have a different test site?

Bugtraq seems to be holding my posts lately so if you don't see this
please relay it to the list.

On Wednesday, December 10, 2003, at 02:26 PM, Andreas Plesner Jacobsen
wrote:

> On Wed, Dec 10, 2003 at 12:13:57AM +0000, Pedro Castro wrote:
>>>> From: <bugtraq (at) zapthedingbat (dot) com [email concealed]>
>>>> To: bugtraq (at) securityfocus (dot) com [email concealed]
>>>> Subject: Internet Explorer URL parsing vulnerability
>>>>
>>>> Internet Explorer URL parsing vulnerability
>>>> Vendor Notified 09 December, 2003
>>>>
>>>> # Vulnerability ##########
>>>> There is a flaw in the way that Internet Explorer displays URLs in
>>>> the address bar.
>>>>
>>>> By opening a specially crafted URL an attacker can open a page that
>>>> appears to be from a different domain from the current location.
>>>>
>>> This exploit also applies to the Macintosh version of Explorer
>>> v5.2.3(5815.1)
>>
>> It does also apply to Mozilla Firebird 0.7.
>
> Not the Linux edition, perhaps only on Windows?
>
> --
> Andreas Plesner Jacobsen | Owe no man any thing...
> | -- Romans 13:8
>
>

Charles Richmond Implemented Integrated Systems Corporation
cmr (at) iisc (dot) com [email concealed] cmr (at) acm (dot) org [email concealed] YIM:cmriisc http://www.iisc.com
O/S, I18N, Systems Development, Process and Integration Providers
131 Bishop's Forest Drive , Waltham , Ma. USA 02452
(781) 647 2246 FAX (781) 647 3665 Cellular (781) 389 9777

[ reply ]
Re: Internet Explorer URL parsing vulnerability (Yes, Mozilla too.) Dec 11 2003 06:31PM
netmask (netmask enZotech net)


 

Privacy Statement
Copyright 2010, SecurityFocus